Description
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
Timeline
| 2026-01-01: | Advisory disclosed |
| 2026-01-01: | VulDB entry created |
| 2026-01-01: | VulDB entry last update |
Credits
gets (VulDB User)
References
vuldb.com/?id.339345 (VDB-339345 | EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted upload)
vuldb.com/?ctiid.339345 (VDB-339345 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.721346 (Submit #721346 | EmpireSoft EmpireCMS <= 8.0 Unrestricted Upload)
note-hxlab.wetolink.com/share/28QXRLje7Uz1
note-hxlab.wetolink.com/share/28QXRLje7Uz1
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.